Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Paloalto Networks PSE-Cortex Practice Exam with Questions & Answers | Set: 2

Questions 11

An Administrator is alerted to a Suspicious Process Creation security event from multiple users.

The users believe that these events are false positives Which two steps should the administrator take to confirm the false positives and create an exception? (Choose two )

Options:
A.

With the Malware Security profile, disable the "Prevent Malicious Child Process Execution" module

B.

Within the Malware Security profile add the specific parent process, child process, and command line argument to the child process whitelist

C.

In the Cortex XDR security event, review the specific parent process, child process, and command line arguments

D.

Contact support and ask for a security exception.

Questions 12

"Bob" is a Demisto user. Which command is used to add 'Bob" to an investigation from the War Room CLI?

Options:
A.

#Bob

B.

/invite Bob

C.

@Bob

D.

!invite Bob

Questions 13

The certificate used for decryption was installed as a trusted toot CA certificate to ensure communication between the Cortex XDR Agent and Cortex XDR Management Console. What action needs to be taken if the administrator determines the Cortex XDR Agents are not communicating with the Cortex XDR Management Console?

Options:
A.

add paloaltonetworks.com to the SSL Decryption Exclusion list

B.

enable SSL decryption

C.

disable SSL decryption

D.

reinstall the root CA certificate

Questions 14

When preparing the golden image in a Cortex XDR Virtual Desktop Infrastructure (VDI) deployment, which step is required?

Options:
A.

Disable automatic memory dumps.

B.

Scan the image using the imagepreptool.

C.

Launch the VDI conversion tool.

D.

Enable the VDI license timeout.

Questions 15

Which step is required to prepare the VDI Golden Image?

Options:
A.

Review any PE files that WildFire determined to be malicious

B.

Ensure the latest content updates are installed

C.

Run the VDI conversion tool

D.

Set the memory dumps to manual setting

Questions 16

A prospective customer is interested in Cortex XDR but is enable to run a product evaluation.

Which tool can be used instead to showcase Cortex XDR?

Options:
A.

Test Flight

B.

War Game

C.

Tech Rehearsal

D.

Capture the Flag

Questions 17

When integrating with Splunk, what will allow you to push alerts into Cortex XSOAR via the REST API?

Options:
A.

splunk-get-alerts integration command

B.

Cortex XSOAR TA App for Splunk

C.

SplunkSearch automation

D.

SplunkGO integration

Questions 18

A General Purpose Dynamic Section can be added to which two layouts for incident types? (Choose two)

Options:
A.

"Close" Incident Form

B.

Incident Summary

C.

Incident Quick View

D.

"New"/Edit" Incident Form

Questions 19

An antivirus refresh project was initiated by the IT operations executive. Who is the best source for discussion about the project's operational considerations'?

Options:
A.

endpoint manager

B.

SOC manager

C.

SOC analyst

D.

desktop engineer

Questions 20

For which two purposes can Cortex XSOAR engines be deployed? (Choose two.)

Options:
A.

To execute recurring daybooks based on specific time schedules or changed to a feed

B.

To add processing resources for a heavily-used integration via load-balancing groups.

C.

To integrate with tools in a network location that the Cortex XSOAR server cannot reach directly

D.

To connect Cortex XSOAR to all required Palo Alto Networks resources such as the Cortex Gateway

Exam Code: PSE-Cortex
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks System Engineer - Cortex Professional
Last Update: Jul 13, 2025
Questions: 168